Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request forgery (SSRF) and potentially cross-site scripting (XSS). This vulnerability exists due to an incomplete fix for CVE-2025-58179. Fixed in 5.13.10.
History

Wed, 29 Oct 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Withastro
Withastro astro
Vendors & Products Withastro
Withastro astro

Tue, 28 Oct 2025 20:00:00 +0000

Type Values Removed Values Added
Description Astro is a web framework that includes an image proxy. In versions 5.13.4 and later before 5.13.10, the image proxy domain validation can be bypassed by using backslashes in the href parameter, allowing server-side requests to arbitrary URLs. This can lead to server-side request forgery (SSRF) and potentially cross-site scripting (XSS). This vulnerability exists due to an incomplete fix for CVE-2025-58179. Fixed in 5.13.10.
Title astro allows bypass of image proxy domain validation leading to SSRF and potential XSS
Weaknesses CWE-79
CWE-918
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-10-28T19:54:28.683Z

Updated: 2025-10-28T19:54:28.683Z

Reserved: 2025-09-22T14:34:03.471Z

Link: CVE-2025-59837

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-28T20:15:49.170

Modified: 2025-10-28T20:15:49.170

Link: CVE-2025-59837

cve-icon Redhat

No data.